← Späť na vyhľadávanie CVE

CVE-2026-16256

POUCO Import Users

Popis

The POUCO Import Users WordPress plugin through 1.0.0 does not perform any capability or nonce checks on AJAX actions available to unauthenticated users that create and update WordPress accounts, and it trusts an attacker-supplied role value, allowing unauthenticated attackers to create a new administrator account and take over the site.

CVSS 9.8EPSS 0.303%Riziko 1.01
Zobraziť zdroj
Zverejnené
2026-08-02 06:16:39
Dotknuté verzie
<=1.0.0
Typ
Webová aplikácia
Posledná úprava
2026-08-05 17:16:43
Vektor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H